Skip to main content
ISACA

ISACA

ISACA® (www.isaca.org) represents the global workforce advancing trust in technology. For more than 55 years, ISACA has empowered its global community of 195,000+ members with the knowledge, credentials, training and network they need to thrive in fields like information security, governance, assurance, data privacy, risk management and emerging tech. With a presence in 195 countries and with nearly 230 chapters worldwide, ISACA offers resources tailored to every stage of members’ careers—helping them to thrive in a rapidly changing digital landscape, drive trusted innovation and ensure a more secure digital world. Through the ISACA Foundation, ISACA also champions IT education and career pathways for underrepresented and underresourced communities, fostering a diverse and inclusive technology workforce.www.isaca.org

Search complete. 34 mentions across 19 episodes found for "ISACA".

Sep 17, 2026

Sec GuyHOST
2:55
ISO is how you survive the audit.
Sec GuyHOST
2:58
Finally, we have COVID, which was created by ISACA, the same organization that writes your exam.
Sec GuyHOST
3:06
COVID is designed to bridge the gap between IT operations and overarching business goals, ensuring every dollar spent directly supports a business objective.
Sec GuyHOST
3:17
But who decides which framework to use? Most engineers fail here because they think the security team makes this choice.
Sec GuyHOST
4:47
Procedures are the step-by-step manuals.
Sec GuyHOST
4:50
They tell the firewall engineer exactly which buttons to click to turn on that encryption.
Sec GuyHOST
4:56
ISACA loves to test your understanding of this hierarchy.
Sec GuyHOST
5:01
If they ask which document is high level and mandatory, the answer is policy.
Sec GuyHOST
0:57
Let's get to work.
Sec GuyHOST
0:59
We need to understand ISACA's core philosophy.
Sec GuyHOST
1:02
ISACA is the governing body for the CISM, and they demand a strict separation of duties.
Sec GuyHOST
1:08
On the left, we have IT operations.
Sec GuyHOST
1:12
This is the engineering team.
Sec GuyHOST
2:00
You must justify every single dollar of your security program based on the current risk environment.
Sec GuyHOST
2:07
ISACA loves this concept because it forces constant, rigorous business alignment.
Sec GuyHOST
2:13
Now, let's look at a real-world scenario.
Sec GuyHOST
2:16
Imagine we are in an economic recession.
Sec GuyHOST
0:43
A technician sees a critical software flaw and immediately demands an emergency patch, even if it takes down the payment server.
Sec GuyHOST
0:51
A CISO looks at that same flaw and asks, does this actually threaten our core business operations? To answer that, we use three distinct metrics that ISACA loves to test.
Sec GuyHOST
1:04
Risk capacity, risk appetite, and risk tolerance.
Sec GuyHOST
1:09
Risk capacity is the absolute maximum amount of risk a company can absorb before it goes completely bankrupt.
Sec GuyHOST
0:42
To pass the CISM exam and survive the CISO chair, you must master the science of measurement.
Sec GuyHOST
0:48
ISACA defines three specific indicators, KGIs, KPIs, and KRIs.
Sec GuyHOST
0:55
Let's break them down by time, past, present, and future.
Sec GuyHOST
1:00
First, the past, KGI, key goal indicator.
Jake BernardesGUEST
0:16
So I would get out there, right? Go join local communities.
Jake BernardesGUEST
0:19
ISACA and ISSA chapters all over the world.
Jake BernardesGUEST
0:21
Go join those kind of communities in groups or B-Sides events or go to conferences.
Jake BernardesGUEST
0:27
Network via LinkedIn.

17 MINS LATER

Jake BernardesGUEST
17:46
I think the most important thing to anybody in business, not just in cybersecurity, is your network.
Jake BernardesGUEST
17:51
So I would get out there, right? Go join local communities.
Jake BernardesGUEST
17:55
ISACA and ISSA chapters all over the world.
Jake BernardesGUEST
17:57
go join those kind of communities in groups or B-Sides events or go to conferences, like network via LinkedIn, reach out to people who you think are interesting and ask them if you can have 30 minutes to learn from them.
Menno van der HorstHOST
0:26
Cool.
Ramsés GallegoGUEST
0:26
I'm an ISACA Hall of Fame, president of the ISACA Barcelona chapter, and again, super excited to be with you this morning, guys.
Menno van der HorstHOST
0:32
Awesome, it's an honor.
Menno van der HorstHOST
0:34
So, uh, I have Quint as well, Quint Ketting, our, uh, regular table guest, my co-host.

7 MINS LATER

Ramsés GallegoGUEST
8:03
[laughs] So two questions, right? Is it good for right now, and is it good for tomorrow?
Quint KettingHOST
8:06
Exactly.
Quint KettingHOST
8:07
And, and I think, uh, and that's why I wanted to switch gears, because, um, you are also, uh, a leader in the ISACA community, right?
Ramsés GallegoGUEST
8:16
Yes.
AamirGUEST
26:07
That is clear.
AamirGUEST
26:10
I mean, like we talk about the ISACA, For CISA, they have AIA.
AamirGUEST
26:17
For CSM, they have AISM.
AamirGUEST
26:19
For the series, they have AIR.
speaker_1HOST
2:42
Yes.
speaker_1HOST
2:42
Stuff like, um, CompTIA's SecAI+ or ISACA's AAISAM.
speaker_0HOST
2:49
Mm.
speaker_1HOST
2:49
These rely really heavily on multiple choice questions, just, you know, A, B, C, or D.
Lisa CookHOST
25:54
My name, again, is Lisa Cook.
Lisa CookHOST
25:56
I'm the GRC Principal Researcher at ISACA.
Lisa CookHOST
26:00
And thank you so much for joining us.
Lisa CookHOST
26:03
Thank you, Lisa.

9 more episodes mention ISACA.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.